Agentic Commerce Through My Lens: A new infrastructure is being built to enable AI agents to make purchases on behalf of humans autonomously.
Imagine an IoT (Internet of Things) device such as a Wi-Fi-enabled intelligent refrigerator purchasing groceries when stocks are running low. This article explores the basic concepts of agentic commerce and how it works.
It also comes with an evergreen dictionary of terms intended to help readers understand the new terminology that agentic commerce brings to the payment landscape.
Terminology
Terminology count
:
—
|
As of:
—
What is agentic commerce?
Let's break this term down into two parts: agentic and commerce.
Agentic is an adjective used to describe a non-human entity engineered to perform a set of predefined tasks independently, based on conditions and instructions defined by humans.
As the underlying systems become more sophisticated—for example, through additional logic and decision-making capabilities—they can perform increasingly complex tasks.
Today, the term ‘agentic’ is used in several contexts—for example, agentic processing and agentic AI systems, where components can be orchestrated to perform tasks and produce results with a degree of autonomy.
Commerce, in this context, refers to the buying and selling of goods or services. So, agentic commerce is a transaction performed by an artificial intelligence that has been given sufficient instructions to execute a payment flow end to end on behalf of a human.
Who are the key players?
Agentic commerce has emerged through developments across the AI, technology and payments industries. Anthropic introduced the Model Context Protocol (MCP), an open standard for connecting AI systems to external tools and data, while payment networks such as Mastercard and Visa subsequently introduced infrastructure designed to enable AI agents to transact securely on behalf of consumers.
Other major players in the payments industry, including fintech companies such as Stripe and payment networks such as Visa and Mastercard, have also contributed to making agentic commerce a reality.
What type of transaction is an agentic payment?
In my opinion, an agentic commerce transaction is, in essence, a card-not-present tokenized transaction, although I have not yet seen the payment message (ISO or API) itself to confirm this.
At the time of writing, an AI agent is not considered a legal entity with the legal capacity to apply for and own a payment credential with a financial institution.
Therefore, to make purchases autonomously on behalf of a legal entity, the AI agent needs a preconfigured payment credential that can be presented at the payment interface during checkout.
For payments to be initiated and completed autonomously, an AI agent would need to be bound by a set of conditions under which it is expected to operate.
It is critical to enforce the domain restrictions under which an AI agent can operate to manage risks related to fraud, uncontrolled purchases, and emerging agentic payment risks.
These conditions or domain restrictions can take the form of rules or configured parameters, for example:
(1) Purchase within a preset budget.
(2) Purchase from a group of merchants identified by a Merchant Category Code (MCC).
(3) Purchase within the criteria defined by the user to prevent uncontrolled spending.
(4) Purchase using a specific payment credential that is configured to allow agentic payments.
These capabilities are possible today because they can leverage existing payment tokenization rails, which provide a sophisticated and secure way to make payments.
How does agentic commerce occur?
Agentic commerce can operate autonomously (without human intervention) or semi-autonomously (human-in-the-loop mode).
As the technology is nascent, methods are still being defined to support both modes.
It is important to note that automated payments already exist in the form of subscriptions, where recurring payments are triggered when certain conditions are met—for example, your Netflix or Coursera subscription payment.
An automated payment is not an agentic payment because there is no defined AI agent initiating the payment. A human originally initiated the first transaction and subscribed to a service, with subsequent payments processed as Merchant-Initiated Transactions (MITs).
An automated payment that is a card-not-present transaction would typically follow an initial transaction during which strong authentication or identity verification is performed, e.g., Strong Customer Authentication (SCA).
What defines the identity of an AI agent?
An AI agent would need to be identifiable for traceability so that the initiator of a payment can be determined. In a contact or contactless transaction, various parameters in the payment message indicate whether the transaction was initiated using a card or a token provisioned to a digital wallet.
An AI agent's identity could be established by the authority that created it. However, at the time of writing, I have not found public articles or specifications from trusted authorities describing how the identity of an AI agent is defined.
It may be a sophisticated form of tokenized identifier, with additional identifying data, conditions, or domain restrictions associated with it to uniquely identify the AI agent.
Why is it important to know the identity of an AI agent?
Trust is an important pillar of the payment ecosystem. It is built and sustained through transparency, with mechanisms embedded in payment transactions to help combat fraud.
Knowing who initiated the payment provides clarity as to whether the transaction was authorized by the legitimate owner of the payment credential and whether it was initiated by the intended party.
To be continued…
This is the first article in my Agentic Commerce series.
I plan to revisit the topic on a quarterly basis as the ecosystem evolves, with each article exploring new developments and questions emerging across agentic commerce and payments.